Beveiligingsadvies

CVE-2026-10551

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-13 06:00:01
Laatst bijgewerkt 2026-07-13 15:54:20
Toegewezen door WPScan
CVSS-score 6.1
Status PUBLISHED

Beschrijving

The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format.